There is no peace for Trezor: 347,000 emails exposed after the attack on the supplier

Written by Jason Miller

Trezor has alerted its customers to a new breach involving, once again, not its internal systems but a third-party vendor. The attack hit Shortthe marketing platform that the hardware wallet manufacturer uses to send newsletters, and was sufficient to expose approximately 347,000 email addresses of the membership database.

The attackers used the access obtained to send emails that completely imitated the company’s official communications, complete with a spoofed sender. (email protected). The subject chosen to deceive recipients was alarming: “Critical Security Alert: STM32 Entropy Vulnerability”, a fake alert about an alleged flaw in the microcontroller of Trezor devices.

Anyone who clicked on the link included in the message was directed to download an application that required entering the wallet backup password: the data which, once in the hands of criminals, allows the funds held on the blockchain to be irreversibly dried up.

A race against time

Trezor claims to have disabled the malicious domain by 20 minutes from the discovery of the attack, limiting the damage to approx 2,500 users who had already clicked on the link before the suspension. In the official press release, the company specifies that no Trezor product, wallet or account system has been compromised: the problem remains confined to the newsletter database managed by Brevo.

However, this is no small detail, considering that the addresses that end up in the wrong hands could be reused for future phishing campaigns. Trezor has made it known that it is reevaluating its relationships with its external suppliers, evidently the recurring weak point in its security chain.

This is in fact the second accident in just two months. Trezor had already had to notify customers of a breach in August ShipMonkthe logistics partner in charge of shipping, hit by a critical SQL injection vulnerability on the Metabase platform.

In that case, names, shipping addresses, e-mails and telephone numbers were exposed: initial estimates spoke of around 14,000 US customers involved, which later rose to 81,000 people in total after a more in-depth investigation, also impacting buyers in Brazil, Colombia, Italy, Portugal, Sweden and the United Kingdom for orders placed between May 10 and August 8.

In the weeks following the ShipMonk data leak, some users received paper letters with fake QR codes that linked to phishing pages, an attack vector that also exposes cryptocurrency holders to the risk of so-called “wrench attacks”, physical attacks aimed at extorting passwords. Trezor had already suffered a similar episode in January 2024, when the breach of its customer support portal exposed the data of around 66,000 users.

Jason Miller

I'm Jason Miller, and I've been passionate about technology and storytelling for over a decade. As a lead writer at Herald Editorials, I strive to bring clarity and creativity to complex tech topics. When I'm not writing, you'll find me exploring the latest gadgets or hiking in the great outdoors.